Hostexploit's World Hosts Report
Total Page:16
File Type:pdf, Size:1020Kb
HostExploit’s World Hosts Report September 2013 Abstract For the first time, hosts registered in a single country –the United States – occupy the worst three places in the Top 50 list of hosts and networks. Examining hosting practices and standards is as relevant as ever in the quest for much needed improvements to a system that has few enforceable restraints. Quantification through the measurement levels of cybercriminal activity on servers around the world is one way to achieve this aim. Since 2009, HostExploit’s World Hosts Report (formerly Top 50 Bad Hosts) has been examining all 44,000+ publicly-routed Autonomous Systems in the world, gathering data on infected websites, botnets, spam and other activity, before combining the research with trusted community sources and to arrive at a reliable analysis of the results. The report makes suitable reading for service providers, security professionals, webmasters and policymakers alike. For the most part, the reader is left to draw their own conclusions, as numbers speak for themselves. However, it should be stressed that most malicious content is not hosted knowingly – often it is as a result of inaction, and sometimes hosts can be the victims. However, it remains true that all cybercrime, cyber-attacks, and Internet badness is hosted from someone and from somewhere; i.e. located on and allocated to an ASN. So it makes sense that this is where we should start in the continuing quest for solutions. - Jart Armin ISBN 978-0-9836249-6-7 World Hosts Report - September 2013 Comparative Data Editor In association with ECYFED AA419 Jart Armin Abuse.CH Clean-MX.DE Reviewers Cyscon SIRT Dr. Bob Bruen Emerging Threats Raoul Chiesa Google Safe Browsing Peter Kruse Group-IB Andre’ DiMino HostExploit Thorsten Kraft hpHosts Andrey Komarov ISC Godert Jan van Manen KnujOn Steven Dondorp MalwareDomains Edgardo Montes de Oca MalwareDomainList Contributors RashBL Steve Burn Robtex Greg Feezel Shadowserver Andrew Fields SiteVet David Glosser Spamhaus Niels Groeneveld SRI International Matthias Simonis StopBadware Will Rogofsky SudoSecure Philip Stranger Team Cymru Bryn Thompson The Measurement Factory DeepEnd Research UCE-Protect Partner of the ACDC project 2 Table of Contents World Hosts Report - September 2013 Introduction ����������������������������������������������������������������������������������������������������4 Editorial 4 Disclaimer 4 Frequently Asked Questions ������������������������������������������������������������������������5 Methodology 5 Definitions 5 Top 50 Hosts ���������������������������������������������������������������������������������������������������6 Top 10s ������������������������������������������������������������������������������������������������������������7 Top 10 Visual Breakdown 7 Top 10 Newly Registered 7 Top 10 Countries 8 Hosts by Topic ������������������������������������������������������������������������������������������������9 Infected Web Sites 9 Botnet C&Cs 10 Spam 11 Phishing 12 Current Events 13 Zeus Botnets 14 Exploits 15 Badware 16 Appendix 1: Glossary �����������������������������������������������������������������������������������17 Appendix 2: Methodology ���������������������������������������������������������������������������19 3 World Hosts Report - September 2013 Introduction Editorial For the first time, hosts registered in a single country – the United States – occupy the worst three places in the Top 50 list of hosts and networks. The top three hosts are AS33182 HostDime.com, AS26347 DreamHost, and AS11042 Landis Holdings. The report, spanning the three months of Q3 2013, ranks hosts by the highest observed concentrations of malicious activity, such as malware, spam and botnets. This, of course, is not a record to be proud of. Over a long period of time, respected sources have warned of the high levels of malicious activity found in the United States, particularly as relating to phishing1,2. What are the causes for this? The main reasons include: Get in touch • Plentiful and cheap hosting� • More integration with anonymity services� Most domains registrars and web hosts If you like what we do and would like offer ‘whois proxy’ services, and increased options to purchase via Bitcoin. to be involved, why not become a HostExploit sponsor or partner? • Enhanced reputation� Less chance of being blocked by country, and a more reputable look for phishing scams. We are continually looking to improve on what we do by However, it is not all bad news for the United States – the Country listings show a downward expanding our outreach. movement to No. 9 from No. 5. Exceptionally good individual performances from previous high-ranking hosts (including AS21740 eNom, ranking 1150, and AS33626 Oversee, ranking If you think you can be of assistance, 943) help contribute to this improved status. we would love to hear from you. Get in touch at [email protected] So the over-riding good news is: it is possible for hosts to clean up. But what incentives are there to do so? At the moment, legally, there is very little, Cross-border action is notoriously complex and consumer rights vary from country to country, if they exist at all. In the US, for example, ISPs are resisting FCC attempts to introduce industry standards and accountability that could open the door to the imposition of financial penalties for failing to protect consumers. But even without pecuniary punishments, it just makes good sense for a host to abide by good practices and to make every reasonable effort to remain clean. The benefits are manifold - is better for business, for the economy and for national security. Disclaimer Every reasonable effort has been made to assure that the source data for this report was up to date, accurate, complete and comprehensive at the time of the analysis. However, reports are not represented to be error-free and the data we use may be subject to update and correction without notice. HostExploit or any of its partners including CyberDefcon, Group-IB and CSIS are not responsible for data that is misrepresented, misinterpreted or altered in any way. Derived conclusions and analysis generated from this data are not to be considered attributable to HostExploit or to our community partners. This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivs 3.0 Unported License. Please contact CyberDefcon to use this work. 1 http://www.zdnet.com/blog/security/how-many-people-fall-victim-to-phishing-attacks/5084 2 http://www.gartner.com/newsroom/id/936913 4 Frequently Asked Questions World Hosts Report - September 2013 Methodology Definitions In December 2009, we introduced the HE Index as a numerical representation of the ‘badness’ of an Autonomous System (AS). Although generally well-received by the community, we have IPs since received many constructive questions, some of which we will attempt to answer here. Throughout the report, the field “IPs” refers to the number of originating IPv4 addresses allocated to the AS. Why doesn’t the list show absolute badness instead of proportional badness? In the context of countries, it is the A core characteristic of the index is that it is weighted by the size of the allocated address sum of the “IPs” for each AS in that space of the AS, and for this reason it does not represent the total bad activity that takes country. place on the AS. Statistics of total badness would, undoubtedly, be useful for webmasters and system administrators who want to limit their routing traffic, but the HE Index is intended to highlight security malpractice among many of the world’s internet hosting Country providers, which includes the loose implementation of abuse regulations. Since an AS will usually be physically routed across multiple countries, HostExploit determines the most Shouldn’t larger organizations be responsible for re-investing profits in better security prominent country of origin for ASes regulation? based on their routing locations and The HE Index gives higher weighting to ASes with smaller address spaces, but this registration data. relationship is not linear. We have used an “uncertainty factor” or Bayesian factor, to model this responsibility, which boosts figures for larger address spaces. The critical address size has been increased from 10,000 to 20,000 in this report to further enhance this effect. HE Index HostExploit’s quantitative metric, representing the concentration of If these figures are not aimed at webmasters, at whom are they targeted? malicious activity served from an The reports are recommended reading for webmasters wanting to gain a vital understanding Autonomous System. of what is happening in the world of information security beyond their daily lives. Our main goal, though, is to raise awareness about the source of security issues. The HE Index quantifies the extent to which organizations allow illegal activities to occur - or rather, fail HE Rank to prevent it. Rank of the Index compared to all 44,556 ASes. Why do these hosts allow this activity? Please see the Glossary for further It is important to state that by publishing these results, HostExploit does not claim that definitions. many of the hosting providers listed knowingly consent to the illicit activity carried out on their servers. It is important to consider many hosts are also victims of cybercrime. 5 World Hosts Report - September 2013 HE Rank HE Index ASN Name Country IPs 1 252.33 33182 HostDime�com, Inc� US 63,232 2 249.28 26347 New Dream Network, LLC US 230,656 3 243.51 11042 Landis Holdings